Daily OT Security News: August 30, 2026

Viakoo OT/IoT cybersecurity briefing — August 30, 2026.

Boston Scientific Says Cybersecurity Incident Continues to Disrupt Operations

On August 29, 2026 Boston Scientific said its investigation into a cybersecurity incident is ongoing and that the unauthorized activity is limited to certain on‑premise systems, with no identified impact to cloud‑based systems and applications. The company said the disruption has affected manufacturing, product ordering, and shipment processing, and that new remote‑monitoring activations for some cardiac rhythm management devices are affected while previously active remote monitoring and implantable device function are not known to be impacted.

Source: Boston Scientific Newsroom

DOJ and FBI Disrupt PRC-Linked IoT Botnet and Hacking Platforms

On August 26, 2026 the Justice Department and FBI announced court‑authorized seizures targeting QScan and QTRouter, platforms the agencies said were allegedly operated by PRC state‑sponsored group QTFY to target U.S. critical infrastructure and sensitive networks. The release states QScan automatically scanned and infected thousands of IoT devices, and that QTRouter used compromised IoT devices, proxy services, and leased virtual private servers as an obfuscation network to conceal the origin of intrusion activity.

Source: U.S. Department of Justice

More Than 100 U.S. Water Systems Targeted Through Exposed OT

BankInfoSecurity reported on August 26, 2026 that CISA observed more than 100 internet‑exposed water and wastewater systems targeted in attacks during July. The activity commonly involved PLCs directly connected through cellular modems and used internet discovery services to locate reachable systems with misconfigurations, default credentials, or outdated software; CISA recommended removing unnecessary remote access, changing default passwords, applying patches, and replacing unsupported software and devices.

Source: BankInfoSecurity

CISA Warns of Active AI-Assisted Targeting of Siemens S7 PLCs

On August 19, 2026 CISA and partner agencies warned that threat actors are conducting reconnaissance and capability development against U.S. Siemens S7 PLC installations, using AI‑generated exploitation scripts disguised as legitimate monitoring tools. The advisory says actors are using internet scanning services to find exposed or insufficiently segmented PLCs and may exploit outdated software or weak credentials, and it calls for asset inventory, patching, removal of internet exposure, stronger access controls, and monitoring for unauthorized activity.

Source: CISA

AI Is Lowering the Barrier for Attacks on Everyday Utilities

Axios reported on August 25, 2026 that AI is reducing the time, cost, and specialized expertise required to exploit existing weaknesses in critical infrastructure, citing recent water‑sector activity and a reported four‑day shutdown at a U.K. power plant. The report notes that the underlying exposure problem remains internet‑accessible OT, hard‑to‑patch equipment, and systems that cannot simply be taken offline, while adversaries are gaining speed and scale.

Source: Axios

These items underscore persistent exposure and exploitation risks to OT/IoT systems and the continued need for inventory, segmentation, patching, credential hygiene, and monitoring.

Share this